W
Reviewed by Jacob Whitmore, Whito · Fact-checked for accuracy

Last Updated on September 8, 2026

MSPs are unusual in one way that shapes everything: your buyers look almost exactly like you. 58 per cent of UK cyber security firms have one to nine employees, and 44 per cent of micro businesses use an external provider. This is small firms selling to small firms.

Start: is anything about you independently checkable?

You are at Start if any of these is true.

  • No ICO registration number on the site.
  • No Cyber Essentials certificate reference, or one with no date.
  • ISO claimed without naming the certification body.
  • No pricing information of any kind, not even a structure.
  • No response or resolution targets published.
  • Your own site has no structured data and no AI crawler policy.

That last one deserves a sentence. In Whito’s July 2026 audit of 120 independent UK business websites, 92 per cent had no AI crawler policy of any kind, about 6 per cent used correct business-type structured data and one site in 120 had a hand-written llms.txt. Being an IT provider whose own site is in the failing 92 per cent is a specific and avoidable embarrassment.

The gate out of Start: a prospect can verify, without contacting you, that you are ICO registered, currently certified, and what your service tiers include.

Build: can you prove you do what you say?

The Build questions in this sector are all about evidence, because evidence is the product.

  • Are response and resolution targets defined by severity and agreed in writing?
  • Do you measure actual performance against them, monthly?
  • Is onboarding documented so it happens the same way every time?
  • Do you produce a client-facing report that a non-technical director can read?
  • Do you know your own churn, and why clients leave?

The report is the underrated one. Most MSPs send a ticket summary. What a director wants is three lines: what broke, what we stopped, what you should decide. A provider that produces that monthly is very hard to replace, because the replacement will not.

The gate out of Build: you can publish last quarter’s actual performance against your own targets without wincing.

Scale: regulation, and what it does to positioning

The Cyber Security and Resilience Bill, introduced on 12 November 2025, expands the regulations to include managed service providers. We could not confirm its current stage, because the Commons Library briefing we opened was last updated on 8 July 2026, and the number of MSPs in scope is not published.

Whatever the timing, the direction is clear and it changes the market in a predictable way. A category that is currently unregulated becomes one where compliance is a threshold. Providers who already publish their registrations, certifications and performance will find that a tailwind. Providers who have sold on relationship alone will find it an audit.

The practical Scale work is unglamorous: a documented service catalogue, consistent contracts, a compliance page that is maintained rather than written once, and enough process that a second technician delivers the same service as the founder.

The channel question

Worth knowing before you budget: we found no UK source publishing MSP lead costs, directory listing fees or cost per lead on any page we could open. There is no paid MSP directory with a published rate card equivalent to what other sectors have.

The NCSC Cyber Advisor directory and the IASME certificate search are both free to appear in by virtue of certification, and IASME explicitly forbids using its search for marketing. So the channels that exist are: referral, local search, certification directories, and being genuinely useful in writing.

That last one suits this sector unusually well, because your buyers are technical enough to tell the difference between real advice and content.

Which stage are you at?

SymptomStageFirst move
Enquiries only from referralStartPublish registrations, certificates and service tiers
Losing to bigger providers on paperworkStart to BuildCyber Essentials, then documented service catalogue
Winning clients and losing them at renewalBuildMonthly client-facing report a director can read
Competing only on per-user priceBuildPublish tiers by contents and response targets by severity
Two technicians delivering different servicesScaleDocumented onboarding and a maintained compliance page

Common questions

How should an MSP price?

In tiers defined by what is included rather than by adjective, per user per month excluding VAT, with a minimum user count and term stated. Published UK ranges run from £25 to £150 per user per month depending on publisher and inclusions, so an unqualified number tells a buyer nothing.

Is fear-based marketing effective for cyber?

Increasingly not, because the government’s own survey publishes a median breach cost of £0 with the middle half from £0 to £200. Continuity, response times, compliance evidence and insurer requirements are all measurable and all survive contact with that figure.

Where do MSP leads actually come from?

Referral, local search and certification directories, on the evidence available. We found no UK source publishing MSP lead costs or a directory rate card, and IASME’s certificate search explicitly forbids use for marketing.

Where does your own business stand?

The structural checks behind this research run on any website in about twenty seconds. Enter yours and read the full result on the page. Free, and we do not ask for your email.

Run the free Visibility Check
author avatar
Whito
Whito is an independent UK research bureau. We ask the AI engines what they recommend, then check the businesses they name against Companies House and the sector registers. Figures we publish carry the date they were checked. Companies cannot pay to appear or to rank.